VORANT. Threat Intelligence Sign in Get the full feed

Trend Micro flaws exploited in the wild

high vulnerability technology

Two Trend Micro product vulnerabilities are already being actively exploited, with attackers able to execute arbitrary code or tamper with components.

Japan's IPA issued an urgent alert regarding multiple vulnerabilities in Trend Micro products that could allow a remote attacker to execute arbitrary code or tamper with product components. Among the disclosed flaws, CVE-2020-8467 and CVE-2020-8468 have already been confirmed as actively exploited in the wild, prompting IPA to warn that damage could expand if organizations do not act quickly.

IPA advises affected organizations to immediately apply the patches provided by Trend Micro and to consult the vendor's official advisories for further technical detail and mitigation guidance. No specific threat actor, malware family, or targeted sector was identified in the alert; the notice is limited to vulnerability disclosure and a call to patch.

Mentioned in this report

Vulnerabilities CVE-2020-8467KEVCVE-2020-8468KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2019/alert20200316.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free